Steps: Set Up Constrained Prospect Security by Country
To set up constrained prospect security, you must have access to these security domains:
- Set Up: Assignable Roles
- Security Configuration
- Set Up: Recruiting
- Set Up: Security Administration
You can set up enhanced prospect security based on a prospect's country, allowing recruiters to view only the prospect data that's relevant to their assigned regions. This feature enables you to customize regions to align with your organization’s structure and helps your organization comply with General Data Protection Regulation (GDPR) requirements by restricting recruiter access by country.
To configure this functionality, you must first create recruiting regions that contain 1or more countries, and then assign roles to those regions. You can assign roles directly on the region or by using the role assignments on location hierarchies you add to the region.
Constrained prospect security by region applies only to prospects and candidates who have prospect records. This security won't apply if a job application exists without a corresponding prospect record.
These steps enable you to configure security for recruiting regions. If you plan to assign roles directly on the
Region of Recruiting
, follow steps 1-3. You can skip steps 1-3 if you only plan to use role assignments with location hierarchies added to the region for recruiting.- Run theMaintain Assignable Rolestask to create a new role.
- AddRegion for Recruitingin theEnabledForcolumn.
- Run theCreate Security Grouptask.
- SelectRole-Based Security Group(Constrained).
- Add a name.
- Select the role created in the previous step.
- Edit the domain security policies for security domains that apply from the attached list.If you need constrained access for specific domains, remove the unconstrained groups and add the constrained groups. (Example: The group you created in step 2).
- Prospects
- Prospect Sharing
- All Prospects
- Candidate: Global Search
- View Confidential Prospects
- Candidate Data: Personal Information and subdomains
- Manage: Prospect Consent
- Candidate Data: SMS Opt-In/Opt-Out
- Manage: Candidates
- Candidate Data: Other Information and subdomains
- Run theCreate Region for Recruitingtasks.
- Enter the Name and Description.
- Select theDefault Regioncheckbox to create a region that covers countries not specified in other regions.
- Select theInactivecheckbox to make the region inactive.
- Select 1 or more countries from the prompt.
- (Optional) Assign 1 or more roles.
- (Optional) Select 1 or more location hierarchies to use the role assignments on those location hierarchies.
- Ensure roles are assigned either directly or through location hierarchies.
- Repeat step 4 for any additional regions as per your requirements.
- (Optional) Run the Regions for Recruiting report to view all the regions that have been set up.
- Copy theFind Candidatesreport to and select the new data source filterInternal and External Candidates Secured by Prospectfor the new report.
- Hide the existing Find Candidates report.
Workday applies the new security constraints to prospect data. After you create or edit regions, assign roles, or add or remove location hierarchies, you must allow 1 to 2 hours for the changes to propagate before the new security takes effect.
As a recruiter assigned to a certain region, login and search for candidates for that region. You can find candidates from your region using either search or the
Find Candidates
report that you created earlier. As expected, you won't be able to find or view candidates from other regions.